Files
2025-11-21 17:17:42 +01:00

1.7 KiB

  • Increase number of containers currently deployed
    • kubectl scale --replicas=3 deployment/nginx
  • Update application version of running containers
    • kubectl set image deployment/nginx-deployment\nginx=nginx:1.9.1 --record
  • Get a shell on a particular container
    • kubectl exec sparcflow/nginx-<container_number> bash
  • Deploy a pod according to YAML manifest file
    • kubectl apply -f <manifest_file>
  • Get a list of running pods
    • kubectl get pods
    • Clean output
      • kubectl get pods -n prod -o="custom-columns=NODE:.spec.nodeName,POD:.metadata.name"
  • Destroy pod
    • kubectl delete -f <manifest_file>
  • Check for service account secrets
    1. mount |grep -i secrets
    2. cat /run/secrets/kubernetes.io/serviceaccount/token
  • Decode JWT secret
    • cat /run/secrets/kubernetes.io/serviceaccount/token | cut -d "." -f 2 | base64 -d
  • Interact with API with pilfered secret:
    1. export TOKEN=$(cat /run/secrets/kubernetes.io/serviceaccount/token)
    2. env - Determine location of API
    3. curl -Lk https://10.100.0.1/api --header "Authorization: Bearer $TOKEN"
  • Check authorization to perform various actions
    • kubectl version auth can-i <action>
    • kubectl version auth can-i get nodes
    • kubectl version auth can-i get pods
    • Make sure you specify namespace with -n if the above succeeds, but the actual action fails. Use namespace specified in the JWT
  • Extract manifest of all pods
    • kubectl get pods -n prod -o yaml > output.yaml
    • Get nicely formatted output:
      • kubectl get pods -o="custom-columns=NODE:.spec.nodeName,POD:.metadata.name,PODIP:.status.podIP,SERVICE:.spec.serviceAccount,ENV:.spec.containers[*].env[*].valueFrom.secretKeyRef,FILESECRET:.spec.volumes[*].secret.secretName"